Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 5.5 CVE-2020-5908 In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files. Big Ip Access Policy Manager after 12.1.5 Fix from $1,6002020-07-01 MEDIUM 5.5 CVE-2020-10750 Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. … Jaeger 1.18.1+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2020-14470 In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repositor… Octopus Deploy 2019.12.2+ Fix from $1,6002020-06-19 HIGH 7.5 CVE-2019-20852 An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or me… Mattermost Mobile 1.26.0+ Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-4477 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in fur… Spectrum Protect Plus after 10.1.5 Fix from $1,6002020-06-15 HIGH 7.5 CVE-2020-10752 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa… Openshift Container Platform Patch available Fix from $1,9502020-06-12 HIGH 7.5 CVE-2020-13223 HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2. Vault 1.3.6 / 1.4.2+ Fix from $1,9502020-06-10 HIGH 7.5 CVE-2020-13881 In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. Debian Linux 2020.1.2+ Fix from $1,9502020-06-06 HIGH 7.5 CVE-2020-13830 An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (J… Android Mitigation only Fix from $1,9502020-06-04 CRITICAL 9.8 CVE-2020-11094 The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each reques… Debugbar 3.1.0+ Fix from $2,3002020-06-04 HIGH 8.8 CVE-2020-3281 A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to vi… Digital Network Architecture Center 1.3.3.3+ Fix from $1,9502020-06-03 HIGH 7.5 CVE-2020-7654 All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG. Broker 4.73.1+ Fix from $1,9502020-05-29 MEDIUM 5.5 CVE-2020-2004 Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshootin… Globalprotect 5.0.9 / 5.1.2+ Fix from $1,6002020-05-13 MEDIUM 5.5 CVE-2020-1698 A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe… Keycloak 9.0.0+ Fix from $1,6002020-05-11 HIGH 8.2 CVE-2020-10712 A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator a… Openshift Container Platform after 4.1 Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-11968 In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that t… Iqrouter Firmware after 3.3.1 Fix from $1,9502020-04-21 MEDIUM 6.2 CVE-2020-6224 SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access u… Netweaver Application Server Java Mitigation only Fix from $1,6002020-04-14 MEDIUM 5.5 CVE-2020-1620 A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of J… Junos Os Evolved 19.3r1+ Fix from $1,6002020-04-08 MEDIUM 5.5 CVE-2020-1621 A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos O… Junos Os Evolved 19.3r1+ Fix from $1,6002020-04-08 MEDIUM 5.5 CVE-2020-1622 A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affec… Junos Os Evolved 19.1r1+ Fix from $1,6002020-04-08 MEDIUM 5.5 CVE-2020-1623 A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all version… Junos Os Evolved 19.2r1+ Fix from $1,6002020-04-08 MEDIUM 5.5 CVE-2020-1624 A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This is… Junos Os Evolved 19.1r1+ Fix from $1,6002020-04-08 HIGH 7.5 CVE-2020-11605 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate i… Android Mitigation only Fix from $1,9502020-04-08 MEDIUM 6.5 CVE-2020-7599 All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publ… Plugin Publishing 0.11.0+ Fix from $1,6002020-03-30 HIGH 7.5 CVE-2019-16528 An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive informa… Abusefilter Patch available Fix from $1,9502020-03-20 MEDIUM 5.5 CVE-2020-5262 In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--… Easybuild 4.1.2+ Fix from $1,6002020-03-19 MEDIUM 5.5 CVE-2020-1753 A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2… Ansible Engine 2.7.18 / 2.8.11+ Fix from $1,6002020-03-16 MEDIUM 6.7 CVE-2019-18576 Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Mal… Xtremio Management Server 6.3.0+ Fix from $1,6002020-03-13 MEDIUM 6.5 CVE-2019-16157 An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being … Fortiweb after 6.2.0 Fix from $1,6002020-03-13 MEDIUM 6.0 CVE-2019-19756 An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of manag… Xclarity Administrator Mitigation only Fix from $1,6002020-03-13